Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":May 12, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
219071 10 危険 シスコシステムズ - Cisco Wireless LAN Controller デバイスにおけるアクセス制限を回避される脆弱性 CWE-362
競合状態
CVE-2014-0703 2014-03-7 16:05 2014-03-5 Show GitHub Exploit DB Packet Storm
219072 7.8 危険 シスコシステムズ - Cisco Wireless LAN Controller デバイスにおけるサービス運用妨害 (DoS) の脆弱性 CWE-399
リソース管理の問題
CVE-2014-0701 2014-03-7 16:04 2014-03-5 Show GitHub Exploit DB Packet Storm
219073 10 危険 シスコシステムズ - 複数の Cisco Wireless-N VPN 製品のファームウェアにおける管理アクセス権を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2014-0683 2014-03-7 15:56 2014-03-5 Show GitHub Exploit DB Packet Storm
219074 7.5 危険 ヒューレット・パッカード - HP Security Management System における任意のコードを実行される脆弱性 CWE-noinfo
情報不足
CVE-2013-6201 2014-03-7 15:47 2013-10-21 Show GitHub Exploit DB Packet Storm
219075 5 警告 Novell - Novell ZENworks Configuration Management の PreBoot サービスにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2013-3706 2014-03-7 15:45 2013-05-30 Show GitHub Exploit DB Packet Storm
219076 6.4 警告 VideoWhisper.com - WordPress 用 VideoWhisper Live Streaming Integration プラグインにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2014-1907 2014-03-7 15:21 2014-02-27 Show GitHub Exploit DB Packet Storm
219077 4.3 警告 VideoWhisper.com - WordPress 用 VideoWhisper Live Streaming Integration プラグインにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2014-1906 2014-03-7 15:20 2014-02-27 Show GitHub Exploit DB Packet Storm
219078 6.5 警告 CMS Made Simple - CMS Made Simple の News モジュールにおける SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2014-2245 2014-03-7 15:19 2014-03-1 Show GitHub Exploit DB Packet Storm
219079 1.9 注意 IBM - IBM Sametime の Connect クライアントにおける重要な情報を取得される脆弱性 CWE-255
証明書・パスワード管理
CVE-2014-0890 2014-03-7 15:12 2014-02-26 Show GitHub Exploit DB Packet Storm
219080 4 警告 IBM - IBM Tealeaf CX の Passive Capture Application の Web コンソールにおけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2013-6720 2014-03-7 15:12 2013-11-8 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:May 12, 2026, 5:06 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
292461 - pluxml pluxml PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID. CWE-200
Information Exposure
CVE-2012-4674 2024-11-21 10:43 2012-08-27 Show GitHub Exploit DB Packet Storm
292462 - thomas_hunter neoinvoice SQL injection vulnerability in application/controllers/invoice.php in NeoInvoice might allow remote attackers to execute arbitrary SQL commands via vectors involving the sort_col variable in the list… CWE-89
SQL Injection
CVE-2012-4673 2024-11-21 10:43 2012-08-26 Show GitHub Exploit DB Packet Storm
292463 - apple ichat_server Apple iChat Server does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via responses for domains that were not asserted. CWE-20
 Improper Input Validation 
CVE-2012-4672 2024-11-21 10:43 2012-08-26 Show GitHub Exploit DB Packet Storm
292464 - psyced psyced psyced before 20120821 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via responses for domains that were not asserted. CWE-20
 Improper Input Validation 
CVE-2012-4671 2024-11-21 10:43 2012-08-26 Show GitHub Exploit DB Packet Storm
292465 - tigase tigase_xmpp_server Tigase XMPP Server before 5.1.0 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via a (1) Verify Response or (2) Author… CWE-20
 Improper Input Validation 
CVE-2012-4670 2024-11-21 10:43 2012-08-26 Show GitHub Exploit DB Packet Storm
292466 - isode m-link M-Link R14.6 before R14.6v14 and R15.1 before R15.1v10 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via responses fo… CWE-20
 Improper Input Validation 
CVE-2012-4669 2024-11-21 10:43 2012-08-26 Show GitHub Exploit DB Packet Storm
292467 - roundcube webmail Cross-site scripting (XSS) vulnerability in Roundcube Webmail 0.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the signature in an email. CWE-79
Cross-site Scripting
CVE-2012-4668 2024-11-21 10:43 2012-08-25 Show GitHub Exploit DB Packet Storm
292468 - darold squidclamav Multiple cross-site scripting (XSS) vulnerabilities in SquidClamav 5.x before 5.8 allow remote attackers to inject arbitrary web script or HTML via the (1) url, (2) virus, (3) source, or (4) user par… CWE-79
Cross-site Scripting
CVE-2012-4667 2024-11-21 10:43 2012-08-25 Show GitHub Exploit DB Packet Storm
292469 - websense websense_email_security The default configuration of the SMTP component in Websense Email Security 6.1 through 7.3 enables weak SSL ciphers in the "SurfControl plc\SuperScout Email Filter\SMTP" registry key, which makes it … CWE-200
Information Exposure
CVE-2012-4605 2024-11-21 10:43 2012-08-23 Show GitHub Exploit DB Packet Storm
292470 - websense websense_web_security The TRITON management console in Websense Web Security before 7.6 Hotfix 24 allows remote attackers to bypass authentication and read arbitrary reports via a crafted uid field, in conjunction with a … CWE-287
Improper Authentication
CVE-2012-4604 2024-11-21 10:43 2012-08-23 Show GitHub Exploit DB Packet Storm